/ Docs
APIDevice enrollment

Exchange Pod Svid

Exchange a scheduled pod's JWT-SVID for a short-lived runtime session. The pod twin of :func:`exchange_device_assertion`: no enrollment token, no device key, no custody row. Attestation is the SVID itself, verified against the SPIRE OIDC discovery JWKS; the entry that lets SPIRE mint it is the scope control. Each SVID buys exactly one session (replay loses on the session row's unique index), so a pod fetches fresh per exchange and entry deletion stops new sessions within one SVID lifetime.

POST
/v1/public/device-assertion/svid-exchange

Authorization

BearerAuth
AuthorizationBearer <token>

Botyard API key — see /docs/authentication.

In: header

Request Body

application/json

TypeScript Definitions

Use the request body type in TypeScript.

A scheduled pod presenting its SPIFFE JWT-SVID for a session.

The SVID is the entire request, same rule as the assertion endpoint: every identity claim lives inside the verified token, so nothing here can assert an identity the SVID does not cover.

Response Body

application/json

curl -X POST "https://example.com/v1/public/device-assertion/svid-exchange" \  -H "Content-Type: application/json" \  -d '{    "svid": "string"  }'
{
  "session_token": "string",
  "session_id": "string",
  "runtime_id": "string",
  "bot_id": "string",
  "device_id": "string",
  "gateway_url": "string",
  "spiffe_id": "string",
  "issued_at": "2019-08-24T14:15:22Z",
  "expires_at": "2019-08-24T14:15:22Z",
  "trust_tier": "user_attached",
  "effect_coverage": "mediated"
}
{
  "type": "string",
  "title": "string",
  "status": 0,
  "detail": "string",
  "instance": "string",
  "error_code": "string",
  "errors": [
    {
      "pointer": "string",
      "detail": "string",
      "type": "string"
    }
  ],
  "trace_id": "string"
}